U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
2026-08-26T01:23:59Z•4a1285c79a5076486959330f8b9c21fc7f604c09776d35aa5789b9a9600d8506
CVE-2026-18963CVE-2026-19478CVE-2026-21962CVE-2026-61979account-takeoveractive-exploitationai-securityauthentication-bypassbackdoorclickfixcritical-infrastructuregitlabkeycloaklinuxmalwaremcpmicrosoft-365model-poisoningnpm-supply-chainoraclepasskeysphishingratrcesamlvulnerabilityweblogicwindowswordpress
What happened
The feed reports a broad set of significant cybersecurity developments, including active exploitation of critical Oracle WebLogic/HTTP Server and GitLab vulnerabilities, severe Keycloak account takeover and miniOrange SAML authentication bypass flaws, AI-agent and notebook command-execution risks, phishing-as-a-service campaigns targeting Microsoft 365, malicious npm packages, malware delivery via fake CAPTCHA pages and gaming sites, RAT and backdoor campaigns, and attacks against critical infrastructure and web servers. Multiple items involve unauthenticated remote compromise, account or data
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 4a1285c79a5076486959330f8b9c21fc7f604c09776d35aa5789b9a9600d8506
- Enrichment time
- 2026-08-26T01:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.